# S3 output requires PutObject on \* Resources

**URL:** <https://discuss.elastic.co/t/s3-output-requires-putobject-on-resources/103457>\
**Category:** Logstash\
**Created:** [October 11, 2017, 3:13am UTC](https://discuss.elastic.co/t/s3-output-requires-putobject-on-resources/103457 "2017-10-11T03:13:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Theodore\_Cowan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theodore_cowan/32/6472_2.png) [@Theodore\_Cowan](https://discuss.elastic.co/u/Theodore_Cowan)\
**Post date:** [October 11, 2017, 3:13am UTC](https://discuss.elastic.co/t/s3-output-requires-putobject-on-resources/103457/1 "2017-10-11T03:13:42Z")

</div>

Posting this so somebody else may avoid spending hours trying to debug the s3 output plugin.

The plugin will throw permissions errors if you do not grant PutObject permissions on bucket resources.

`[2017-10-11T02:53:41,488][ERROR][logstash.outputs.s3] Error validating bucket write permissions! {:message=>"Access Denied", :class=>" Aws::S3::Errors::AccessDenied",`

The IAM policy required is:

```auto
{
    "Statement": [
        {
            "Effect": "Allow",
            "Action": [
                "s3:PutObject"
            ],
            "Resource": [
                "arn:aws:s3:::mybucket*"
            ]
        }
    ]
}

```

---

<div class="post-metadata">

**Author:** ![mujtabahussain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mujtabahussain/32/17514_2.png) [@mujtabahussain](https://discuss.elastic.co/u/mujtabahussain)\
**Post date:** [October 11, 2017, 4:41am UTC](https://discuss.elastic.co/t/s3-output-requires-putobject-on-resources/103457/2 "2017-10-11T04:41:51Z")

</div>

Maybe mark your post as RESOLVED as well so people can see this is a solved issue 🙂

and thanks 🙂

---

<div class="post-metadata">

**Author:** ![mujtabahussain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mujtabahussain/32/17514_2.png) [@mujtabahussain](https://discuss.elastic.co/u/mujtabahussain)\
**Post date:** [October 11, 2017, 4:42am UTC](https://discuss.elastic.co/t/s3-output-requires-putobject-on-resources/103457/3 "2017-10-11T04:42:38Z")

</div>

Also, just a heads up, `Resource` section in CFN should be as restrictive as possible. So instead of `*` give it the buckets that you know need the `s3:PutObject` permission.

---

<div class="post-metadata">

**Author:** ![Theodore\_Cowan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theodore_cowan/32/6472_2.png) [@Theodore\_Cowan](https://discuss.elastic.co/u/Theodore_Cowan)\
**Post date:** [October 11, 2017, 4:58am UTC](https://discuss.elastic.co/t/s3-output-requires-putobject-on-resources/103457/4 "2017-10-11T04:58:18Z")

</div>

That's the exact problem. Specifying a bucket ARN in Resources does not work. I tested the IAM policy limiting access to the specific bucket using the AWS CLI, and it worked as expected. However, it did not work with logstash.

In addition, I was only able to make this work with a bucket in the us-east-1 region (???).

@mujtabahussain I challenge you! Setup Logstash s3 output with logstash-5.4.3-1 to a bucket in us-west-2 region with a IAM user that is appropriately scoped to a single bucket. It will not work. And if it does work, I beg you to show me your configuration.

---

<div class="post-metadata">

**Author:** ![mujtabahussain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mujtabahussain/32/17514_2.png) [@mujtabahussain](https://discuss.elastic.co/u/mujtabahussain)\
**Post date:** [October 11, 2017, 5:03am UTC](https://discuss.elastic.co/t/s3-output-requires-putobject-on-resources/103457/5 "2017-10-11T05:03:43Z")

</div>

> [@Theodore\_Cowan](#):
>
> That's the exact problem. Specifying a bucket ARN in Resources does not work. I tested the IAM policy limiting access to the specific bucket using the AWS CLI, and it worked as expected. However, it did not work with logstash.

My bad. I should read more carefully 🙂

> [@](#):
>
> In addition, I was only able to make this work with a bucket in the us-east-1 region (???).

That seems very strange.

> [@](#):
>
> I challenge you! Setup Logstash s3 output with logstash-5.4.3-1 to a bucket in us-west-2 region with a IAM user that is appropriately scoped to a single bucket. It will not work. And if it does work, I beg you to show me your configuration.

haha ...I shall definitely try 🙂

---

<div class="post-metadata">

**Author:** ![Theodore\_Cowan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theodore_cowan/32/6472_2.png) [@Theodore\_Cowan](https://discuss.elastic.co/u/Theodore_Cowan)\
**Post date:** [October 12, 2017, 4:15am UTC](https://discuss.elastic.co/t/s3-output-requires-putobject-on-resources/103457/6 "2017-10-12T04:15:56Z")

</div>

I've updated my post. I apologize for my temporary insanity. But it did seem that I had a mysterious problem with the s3 output plugin when I really had an unknown VPC Routing Endpoint policy preventing me from performing a PutObject on my bucket.

Thanks for the responses @mujtabahussain. I have it working now.

---

<div class="post-metadata">

**Author:** ![mujtabahussain](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mujtabahussain/32/17514_2.png) [@mujtabahussain](https://discuss.elastic.co/u/mujtabahussain)\
**Post date:** [October 16, 2017, 10:55pm UTC](https://discuss.elastic.co/t/s3-output-requires-putobject-on-resources/103457/7 "2017-10-16T22:55:48Z")

</div>

All good 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 13, 2017, 10:55pm UTC](https://discuss.elastic.co/t/s3-output-requires-putobject-on-resources/103457/8 "2017-11-13T22:55:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
